Microsoft Denies HTTPS Shutdown Was Intentional 69
jbrodkin writes "Microsoft acknowledged that Hotmail's HTTPS encryption service was shut off for users in some countries, but denied that it was because of an intentional ploy to limit email security in countries that have experienced anti-government protests and limits on freedom of expression. 'We do not intentionally limit support by region or geography and this issue was not restricted to any specific region of the world,' Microsoft said. Syria, Morocco, Bahrain, Iran, Lebanon, Jordan and Algeria were among the affected countries, but the problem is now resolved."
I'm inclined to believe them (Score:2, Interesting)
Re: (Score:2)
Hanlon's razor ftw.
Re: (Score:1)
Don't forget the corollary. "Any sufficiently advanced stupidity is indistinguishable from malice." Microsoft lives by this one.
Fool me once, shame on you... (Score:4, Informative)
...but Microsoft is trying to fool us twice [nytimes.com]... yeah, shame on us.
Choice quote below, the parallel with this http "bug" is impressive::
When I originally wrote about this issue [bing Chinese search censorship] back in June, Microsoft protested. “From what you described, that’s not the way Bing is supposed to work,” wrote Kevin Kutz, a company spokesman. He said that Chinese speakers at Microsoft could not replicate my results and did not detect this kind of skewed result. I sent screen shots, and then Microsoft acknowledged the issue but said that it was simply a temporary mistake. “It’s a bug,” Kutz told me. Later, he added: “What’s important is it’s getting fixed.” Soon, he said, Bing searches would be the same for Tiananmen and other sensitive subjects, whatever the language.
(Thanks to pushing-robot for originally posting the link on /. here [slashdot.org].
Re: (Score:2)
Re: (Score:2)
Why would you believe that? These countries are important supporters of the USgovt's War For Terror (TM, all rights reserved and acknowledged) ; the interests of these govts (status quo, continued energy sales) remain aligned,
Re: (Score:3)
I'm inclined to believe them too. As it turns out, by giving root signing keys to Windows to despotic organizations (http://twitter.com/#!/marshray/status/29637858365022208) there is hardly a need to disable HTTPS anyway. As long as you are on a Windows computer, any SSL traffic you send can be intercepted.
Re: (Score:1)
What could be the advantage of such a measure - if it was on purpose?!
I agree, but lives were put at risk (Score:2)
It's understandable that this was a mistake, I suspected that from the beginning, but this doesn't change the fact that Microsoft has put FAR more lives at risk than Wikileaks ever did, so I expect some US military representative to show up on a major news channel any minute now and say Microsoft has blood on their hands. Any minute now.
Just a matter of time.
Still waiting...???
Wow. what a coincidence. (Score:1, Troll)
Re:Wow. what a coincidence. (Score:4, Insightful)
1) HTTPS gets turned off for a few hours in most of Northern Africa and the Middle East, and a few pacific islands
2) Several countries in the Middle East are experiencing unrest, therefore
3) IT MUST BE INTENTIONAL!!11
Re: (Score:3)
Re: (Score:1)
Correlation != Causation
If you've been on the internet for more than 5 minutes you'd already know that by now.
Re: (Score:2)
Correlation != Causation
Right you are.
Re: (Score:1)
Re: (Score:2)
no, but the two are highly correlated.
Re: (Score:3)
They've only had the thing available for four and a half months. The Tunisian protests started over 3 months ago.
This current unrest covers over 72% of the total time the feature has been available. Why would you expect it to have happened in the tiny window before them?
Re: (Score:2)
why did such a thing NOT happen at any given point, before ?
Good question. At any given time in history, there is civil unrest going on somewhere in the world. Some oppressive regime will be clamping down on their citizens. So why did this thing NOT happen at all those given points before?
If this was a demonstration of a policy of helping out dictatorships, then why has it not been apparent on previous occasions. I suppose that you could say that this is a new policy, but then that would devalue your intimation that this is proof of malevolent intentions. It could j
Re: (Score:2)
If this was a demonstration of a policy of helping out dictatorships, then why has it not been apparent on previous occasions
well, there was the case with "pirate" software in Russia being investigated only in anti-govt organisations within Russia.
true, MS eventually acknowledged this problem and moved to correct it.
what's more worthy of asking is why even risk the bad PR when MS have no interest in oppression of states with relatively little money.
Re: (Score:1)
Re:Wow. what a coincidence. (Score:4, Insightful)
1) HTTPS gets turned off for a few hours in most of Northern Africa and the Middle East, and a few pacific islands 2) Several countries in the Middle East are experiencing unrest, therefore 3) IT MUST BE INTENTIONAL!!11
Not to take away from your argument (I agree that Hanlon's Razor applies here) but the South Pacific island nation mentioned in the Register story is Fiji, which is currently ruled military junta that regularly practices censorship and suppresses both free speech and fair journalism. Of all the nations mentioned, the only one that I saw that doesn't have a government that's anti-free-press is the Bahamas. (Congo might count, but only because it doesn't really have a functioning government.)
Re: (Score:2)
woah woah woah woah. "They" must be planning something for the Bahamas.
Re: (Score:1)
Re: (Score:2)
It worked for Reagan in Grenada ...
Re: (Score:1)
They didn't want to point it out publicly but the inside work is it was caused upstream by problems with a recent Squid release, a new unknown developer inserted some buggy code that went unchecked. The countries in question use that instead of ISA server (number 1 product in the developed world) which is a little more costly in the short term but saves money over the long run.
Re: (Score:1)
one more, motherfucker!
just one more unsolicited pro-microsoft astroturf and i'm coming after you!
don't think i can't find you, either.
Re: (Score:2, Interesting)
Re: (Score:2)
With this 'accidental' shutdown, microsoft successfully covered all of the countries that were experiencing unrest
Even The Register put a damper on this story: Microsoft: Mystery bug blocks Syrian secure Hotmail - Sun worshipers and fat cats hit too [theregister.co.uk]
Re: (Score:3)
Yep (Score:5, Insightful)
There were people who RTFA and sources (unlike the /. editor who accepted it) the first time around who posted this information in the comments section. There never should have been a story in the first place.
Re: (Score:2)
"Hotmail HTTPS temporarily disabled in scary-dictator-lands" is still news, even if it was the result of a mistake.
Re: (Score:2)
Fair enough, but surely there could have just been one article.
"Well, apparently if you actually RTFA and the sources for TFA, there is this other important bit of information that we left out of the summary in which we jumped to all the wrong conclusions..." (I know this won't quiet down the conspiracy theorists, but the fact that MS was open about this from the beginning makes them a bit more believable than coming out with a new story a few days later).
Re: (Score:2)
I was most amused about the fact that they corrected the story on Slashdot... because they didn't mention Yahoo HTTPS is a paid for service. The actual false story remained up and unchallenged until now, despite the many comments saying it was wrong.
Other countries affected... (Score:2)
"Hotmail users in the affected countries can turn the always-use-HTTPS feature back on by changing the country in their profile to any of the countries in which this feature has not been disabled, such as the United States, Germany, France, Israel or Turkey,"
--------
Sounds "regional" to me *cough*
Incompetance or Malfeasance (Score:1, Flamebait)
Re: (Score:2)
I think I threw up a little.
--
BMO
Re: (Score:2)
probably not too much, or they'd be more believable.
personally i suspect some botman is trying to land a job at MS with all this.
They didn't shut off HTTPS (Score:4, Interesting)
Re: (Score:1)
Re: (Score:2)
Fiji is run by a dictatorship. What is your point?
And the Bahamas and Cayman Islands? What is YOUR point? That the original poster was wrong because of one incorrect example? Do you have any proof that this was some massive international conspiracy?
Re: (Score:1)
"What is YOUR point? That the original poster was wrong because of one incorrect example?"
seems like a fair point to me. List of 18 countries that it's banned in, 3 are non-dictatorships, which is supposed to make some kind of point, except one of those is actually ... a dictatorship.
This is not proof, just evidence.
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Wait... when did a spy agency charged with foreign operations and run by the notoriously corrupt State Department become the trusted source of geopolitical data?
Re: (Score:2)
Re: (Score:2)
Because Microsoft is a huge company and they have processes that prevent random links from being removed from important pages accidentally. At least, I assume they would. Certainly you aren't suggesting that some developer fatfingered ^C (or whatever) and committed it straight to the production environment, are you?
Re: (Score:2)
Because Microsoft is a huge company and they have processes that prevent random links from being removed from important pages accidentally. At least, I assume they would. Certainly you aren't suggesting that some developer fatfingered ^C (or whatever) and committed it straight to the production environment, are you?
The entire web presence of the BBC was off-line last night due to a cockup.
Re: (Score:1)
It was not intentional. No suc^H^H^H agency asked it.
Re: (Score:2)
The real problem (other than morons who love conspiracy theories) is that hotmail https is a mess. I use the hotmail plugin in Outlook and because of that I can't enable https. It breaks the plugin. Yet, my phone can do ssl-based activesync with hotmail.
MS needs to up their game and start fixing https issues. Heck, they should make https the default and stop letting people use weak passwords. I think a live account can have a 4 character password with just letters.
Re: (Score:2)
Or more likely, there was a bug in some change made, and it affected everyone. Just those in the affected countries had mass numbers of people trying to enable it for obvious reasons that it appeared to break there. The rest of the world either had it set or didn't know it existed.
After all, we don't know if it affected people in the US who set it, went "meh" and forgot all about it when it didn't appear to work (or they didn't notice). The folks in the middle east tried it en-masse and noticed it didn't wo
Friends don't let friends (Score:1)
use MS products.
Woul they ever admit to it though (Score:2)
No one ever admits to bending over and taking it up the arse, especially for a country where their regime forces you to silence what they want you to. I guess with all the other MS BS stories running around here, they are trying to bring up their market shares with non sense, just my 2 cents....must be nearing quarter time, and want to up the stats...
Really now... (Score:2)